If you’ve heard NIS 2 mentioned more often lately and assumed it applies mainly to power grids, telecom operators, or public institutions, you’re not alone. Many IT leaders in Bulgaria still see it as a regulatory topic that sits somewhere outside their day-to-day reality.
In practice, NIS 2 is already influencing how IT companies operate, sell, and carry risk – even though the directive has not yet been fully transposed into Bulgarian law for the IT sector.
At its core, NIS 2 is not a technical checklist. It is the European Union’s framework for how organisations are expected to manage cyber risk, handle serious incidents, and remain operational when something goes wrong. Not as a best-practice recommendation, but as a baseline expectation that increasingly shapes contracts, responsibilities, and liability.
Bulgaria’s delay does not remove exposure
Formally, NIS 2 (Directive (EU) 2022/2555) replaces the original NIS Directive and significantly expands its scope. EU Member States were required to transpose it into national law by 17 October 2024. Bulgaria did not meet that deadline, and in May 2025 the European Commission issued a reasoned opinion for failure to notify full transposition.
This delay often creates a false sense of comfort for Bulgarian IT companies. The reality is more nuanced.
NIS 2 is already in force in many other EU countries, and that matters because Bulgarian IT companies rarely operate in isolation. They develop software, host systems, manage infrastructure, or provide support services for clients across Europe – including companies that are already classified as essential or important entities under NIS 2.
When those clients are regulated, their obligations do not stop at their own perimeter. They extend into the supply chain.
How NIS 2 risk moves from clients to IT providers
On paper, NIS 2 applies to organisations in defined sectors such as energy, healthcare, transport, digital infrastructure, financial services, and certain large digital providers.
In practice, IT companies feel NIS 2 through their clients’ behaviour.
Once an organisation becomes accountable for cybersecurity at board level, it starts asking harder questions of the partners it depends on:
- How quickly can incidents be detected and escalated?
- Who is responsible if a service disruption affects operations?
- What controls exist around access, backups, logging, and recovery?
- What happens if an incident originates at a supplier?
This is where NIS 2 quietly reshapes contracts. Security questionnaires become more detailed. Incident-handling clauses become more explicit. SLAs and MSAs begin to include notification timelines, audit rights, and liability language that simply did not exist a few years ago.
You do not need to be named in the directive for its impact to appear in renewals, tenders, and client conversations. We are already seeing this play out in vendor assessments and contract negotiations for 2026.
From technical service to operational liability
Another important shift under NIS 2 is governance. Responsibility for cybersecurity is explicitly placed on management bodies. That changes how incidents are viewed.
What might once have been treated as a technical problem now becomes an operational and leadership issue. Timelines matter. Decisions matter. Documentation matters. Communication matters.
For IT companies delivering services into NIS 2-regulated environments, this creates a very practical form of exposure. A delayed response, an unclear escalation path, or a misconfiguration can quickly move beyond troubleshooting and into questions of accountability and financial loss.
A realistic example
Consider a Bulgarian IT company providing managed infrastructure services to a healthcare provider in another EU country where NIS 2 is already enforced.
A misconfiguration during a routine update causes a service outage. No data is stolen, and systems are restored within hours. Technically, it looks manageable.
However, the healthcare provider is required to assess and document the incident under NIS 2. The outage affects service continuity. Reporting timelines apply. Regulators and internal auditors ask questions.
The client then looks at the contract. Was the IT provider’s response time adequate? Were agreed controls in place? Could the disruption have been prevented?
What started as a technical incident becomes a formal claim for financial loss, operational impact, and additional costs triggered by regulatory obligations. This is where Professional Liability (Errors & Omissions) exposure emerges. If forensic or legal costs follow, Cyber Liability exposure may also come into play.
Resilience, not perfection
NIS 2 does not assume that incidents can be eliminated. It recognises that failures can come from many directions – cyberattacks, human error, supplier issues, misconfigurations, or physical disruption.
That is why it focuses on resilience rather than perfection. Expectations include incident handling, business continuity, backup and recovery, supply-chain security, secure development practices, access controls, training, and authentication.
For most IT companies, this is not about reinventing how they work. In reality, it is about being able to show – under pressure – that risk is managed intentionally and that responses are structured rather than improvised.
Where insurance fits into the picture
Even mature security programmes cannot eliminate risk. What NIS 2 changes is how visible and consequential incidents can become.
This is where insurance plays a practical, stabilising role. Not as a substitute for cybersecurity, but as financial protection when technical issues turn into client claims or regulatory-driven costs.
- Cyber Liability insurance can respond to incident-related costs such as forensic investigations, legal advice, data breach response, ransomware events, and business interruption.
- Professional Liability (Errors & Omissions) insurance becomes relevant when clients allege that an error, omission, or service failure caused financial loss – a common outcome when operational disruption affects regulated entities.
For IT companies operating across borders, these covers are often the difference between absorbing a serious incident and containing its financial impact.
At Broxio, we work with IT and consulting companies to design Cyber and Professional Liability programmes that reflect how risk actually materialises today – through incidents, client expectations, contractual obligations, and claims, not abstract threat scenarios.
If your organisation is seeing more questions around cybersecurity readiness, vendor risk, or incident preparedness – especially from EU-based clients – it may be time to reassess how exposed you really are, and whether your current insurance matches the risk you carry.
